Bundie logoBundie
Security

Security & How Your Funds Are Protected

Understanding Bundie security architecture and protection mechanisms

Security & How Your Funds Are Protected

Bundie is designed with security and transparency first. This guide explains how your funds are protected and what security measures are in place.

Non-Custodial Architecture

You Always Control Your Assets

What this means:

  • Only you can deposit, withdraw, or allocate funds
  • Your private keys never leave your wallet
  • Bundie smart contracts are proxies, not custodians
  • No admin backdoors to access user Accounts

How it works:

Traditional Finance:
You → Bank (holds your money) → Investments
Risk: Bank can freeze, lose, or misuse your funds

Bundie:
You → Your Account (you control) → Yield Strategies
Risk: Only smart contract risk, no custodial risk

Your permissions:

  • Deposit assets to your Account
  • Allocate funds to strategies
  • Withdraw from positions
  • Withdraw from your Account to wallet
  • Recover stuck ETH

Bundie CANNOT:

  • Withdraw your funds
  • Move your assets without approval
  • Freeze your Account
  • Block your withdrawals
  • Access your private keys

Smart Contract Security

Audited Contracts

Bundie's core smart contracts were audited by Sherlock (April 2026), with critical findings fixed before mainnet launch and re-audits run on significant changes. The full report, including severity ratings and remediation status, is public: Bundie Collaborative Audit Report — Sherlock (April 2026).

Deployed Contracts

The full contract stack is deployed on each supported chain: Arbitrum (hub), Base, Optimism, Avalanche, and Scroll (legacy). Select a chain to see its verified addresses.

ContractRoleAddress
AccountManagerFactory & beacon owner for user Accounts0x0e9aA7015773785c1A9dB9d2a8756c952BE096Cf
RouterManagerFactory for protocol routers0x92BF97347ea2037eC8E4b3762B7cCEB8017C255D
BridgeManagerCross-chain bridge modules0x51B7112651867C7D6BC3d9e928F1b0E1839AE936
VaultManagerYield vault adapters (ERC-4626 / ERC-7540)0x101AC7546E60401e52450E4AF291a7396d137996
LayerZero BridgeLayerZero V2 bridge used by BridgeManager0x6b42ABb9b73A51e95B04e3F5C1fA1fE04293A802
ERC-4626 Vault ModuleSync vault adapter0x272a25aB9Ee031eEbE69E2b90A6490eB9B636D0d
ERC-7540 Vault ModuleAsync vault adapter0xe33F804686bB04c70fAC94AfAcfF35438Eaab11c
RelayerFronts native ETH for bridge messaging fees0xC42969B0F0414f6183839F4f6F31B5fD02DaD4e8
FeeManagerFee configuration and collection0xC2226AF5FCa8A5dD5d92CBE1bD93E1B9441e27DC
ContractRoleAddress
AccountManagerFactory & beacon owner for user Accounts0x69c01ED80d5949E222d5638BA44373D3DCF0A4e7
RouterManagerFactory for protocol routers0x7b8af9525F0183909eA985798D415422d875D93d
BridgeManagerCross-chain bridge modules0x55c30aec0b8274347C76265373dcDeb04711BCd2
VaultManagerYield vault adapters (ERC-4626 / ERC-7540)0x40D67F50C5f1EfE784F4B21a09E23eCDf11b1Bd9
LayerZero BridgeLayerZero V2 bridge used by BridgeManager0xF0d20cB080786B3f42C5b6FB2a9D542F82336aA8
ERC-4626 Vault ModuleSync vault adapter0x225457e01544b7516cfcd495c0862371a165F6A8
ERC-7540 Vault ModuleAsync vault adapter0xF2255d2ebd8350DC62B4178dd9904eCE0f8f74d1
RelayerFronts native ETH for bridge messaging fees0x26E550DBFa31362559d5f392d4DCe31Ef321aE87
FeeManagerFee configuration and collection0xD44681613A09B3EA2592D12b94207D6e45361D7d
ContractRoleAddress
AccountManagerFactory & beacon owner for user Accounts0x95CECcd40D98de57F0d93E659e1c966b11A1fb06
RouterManagerFactory for protocol routers0x38Ba8BA3002A1D1984De2ec511D3C9Ffb3F4Ce26
BridgeManagerCross-chain bridge modules0xB4b991FE4aA691a366A08936dA582bE38eDfA690
VaultManagerYield vault adapters (ERC-4626 / ERC-7540)0xD158c69828b4BA5Ad9FCf5c04d67cf7641e4f938
LayerZero BridgeLayerZero V2 bridge used by BridgeManager0x7206bAcACF8F5f5162636f98CD106cdBD60e1d4E
ERC-4626 Vault ModuleSync vault adapter0x655d866C9d0546fFe616A30bbA32CDa6fe06d138
ERC-7540 Vault ModuleAsync vault adapter0x2A40b9b06D58bBFD7dfe36cD9e7B4612Cd82a352
RelayerFronts native ETH for bridge messaging fees0x9964411e45D8A47d6907dc2DAA0a78644AF3C7aa
FeeManagerFee configuration and collection0xa5E9F24444Ce332a9302b8024036f5159199E50A
ContractRoleAddress
AccountManagerFactory & beacon owner for user Accounts0x9673FcfeDbb6C83c4a76f81Bcadf0fc8535EA9C5
RouterManagerFactory for protocol routers0x4793281C20966e39DF90DE21624FF7C3Bb88dDb3
BridgeManagerCross-chain bridge modules0xF203f6261D58EA2d3294a552657890F76f37c9b5
VaultManagerYield vault adapters (ERC-4626 / ERC-7540)0x59e6B4d5B5438d68EBcc25431A041eed660357C7
LayerZero BridgeLayerZero V2 bridge used by BridgeManager0xc7cCA82eE2D7f530A4dc0e6844bfAC7b854F9551
ERC-4626 Vault ModuleSync vault adapter0x541ad2f001106B38668Aee6E7E4BE8164b23A23a
ERC-7540 Vault ModuleAsync vault adapter0x210e466094B3812285796e17Bb7355375aF212D4
RelayerFronts native ETH for bridge messaging fees0xA9Ffe99202BF2903E9405fDb304f4cEd7207473E
FeeManagerFee configuration and collection0x42B93Cc00375479b8EA97041F7b4194fB98DC542

Scroll is supported as a legacy chain. New deposits target current chains; these contracts remain for existing positions.

ContractRoleAddress
AccountManagerFactory & beacon owner for user Accounts0x2E70d2778d143412D66Edf835Be82DB29CB1ECfB
RouterManagerFactory for protocol routers0xFc309ed1FaCd18E942E3a245964D4F94fB4953F9
BridgeManagerCross-chain bridge modules0x2394C009feFf2CC18969FCcB43D49329a2D117fB
VaultManagerYield vault adapters (ERC-4626 / ERC-7540)0x3F669f0368F6F00195B78fdcA0dC8Ea4636568B3
LayerZero BridgeLayerZero V2 bridge used by BridgeManager0xadf8cef9478E1E7B5d8E0e82aF63800693c22176
ERC-4626 Vault ModuleSync vault adapter0x27D10d4E27595C6096F54F231a735e555Af0dD99
ERC-7540 Vault ModuleAsync vault adapter0x6Ed8C9Cd2a2FD7265931E91C73570DAf6f7fF394
RelayerFronts native ETH for bridge messaging fees0x0BE5034494A0210882e1641Ea6B482afAD01A47c
FeeManagerFee configuration and collection0xF9f27e8B4d271827f8C9883aa184bAFFBda073f0

You hold one Account per chain — a personal smart contract deployed as a beacon proxy by AccountManager the first time you use that chain. You can look up your own Account address on the relevant block explorer after creation.

Beacon Proxy Pattern

Your Account is an upgradeable beacon proxy: all Accounts share one implementation, so security patches apply everywhere at once without you migrating funds, and your Account address never changes.

Upgrade safety:

  • A 1-day timelock is enforced by the contract, so every upgrade is announced in advance
  • Upgrades cannot access or move user funds, and all positions are preserved
  • If you're not comfortable with a proposed upgrade, you can withdraw during the timelock

Reentrancy Guards — all deposit, withdrawal, allocation, and cross-chain operations are guarded against reentrancy and recursive-withdrawal attacks.

Whitelisted Tokens — only approved assets can be deposited, which blocks fake or malicious tokens. The current whitelist is USDC, USDT, ETH, and WETH; adding a new token requires a security review and governance approval.

Slippage Protection — every cross-chain deposit, withdrawal, and swap sets a minimum acceptable output. If the result would fall below it (unfavorable rates, fee spikes, low liquidity), the transaction reverts and your funds stay in your Account — you only pay gas.

Validator Trust Model

A validator monitors cross-chain operations and confirms them on-chain — it acts as a notary, not a custodian.

What it does: watches for bridge delivery, confirms completed deposits/withdrawals, and flags failed operations so funds can be refunded.

What it can't do: it holds no keys and has no spending permission, so it cannot move your funds, withdraw on your behalf, block your withdrawals, or fabricate a position you don't actually hold. The worst case is a delay in confirmation, never loss of funds.

Transparency: every validator action is recorded on-chain, so you can independently verify any confirmation against LayerZero Scan and the relevant block explorer.

Bridge Security

Cross-chain moves use LayerZero, an industry-standard messaging protocol used by 100+ protocols and audited by multiple firms. A transfer only updates your Account after the destination chain confirms receipt, and every step is publicly verifiable — the source and destination transaction hashes, the LayerZero message GUID, and the validator's confirmation are all on-chain (track via LayerZero Scan).

Failed Bridge Handling — if a bridge message fails to deliver, the destination protocol rejects the deposit, or an operation gets stuck, the validator flags it as failed on-chain and your funds are refunded to your Account. Manual recovery is available as a last resort, so funds are never permanently lost.

Emergency Recovery

Stuck ETH Recovery — if ETH ever ends up stuck in your Account (an accidental transfer, a refund), you can recover it to your wallet at any time from Account settings. It's a user-only action — no team approval required.

Failed Bridge Recovery

Failed bridges refund automatically (see Failed Bridge Handling above). If a refund doesn't go through, contact support with your operation's message GUID and the team will help you recover — funds are never lost, only delayed, and every recovery action is on-chain and verifiable.

Lost your message GUID? The transaction hash works for recovery too — or contact support with your Account address and the approximate time, and the team can locate the operation on-chain.

Protocol Risk Management

Strategy Vetting Process

Before a strategy is listed it must pass: an independent security audit with no critical findings, a maturity bar (≥ $10M TVL, 90+ days live, no major incidents), an ERC-4626-compatible interface (or a tested adapter), and reliable, manipulation-resistant price oracles. Listed strategies are then monitored continuously for TVL, APY anomalies, and incidents.

Risk Isolation

Position-level isolation:

  • Each position is independent
  • Exploit in one protocol doesn't affect others
  • Your Account holds receipt tokens, not base assets directly

Example:

Your portfolio:
- 1,000 USDC in Aave (Arbitrum)
- 1,000 USDC in Morpho (Base)
- 1,000 USDC in Compound (Optimism)

If Aave is exploited:
 Morpho position unaffected
 Compound position unaffected
 Aave position may lose value
Risk: Limited to 33% of portfolio

Diversification — spreading across protocols and chains means no single point of failure, and bundles diversify automatically.

Incident Response

If an external protocol suffers a security incident, the affected strategy is disabled to new deposits and impacted users are notified (dashboard, email, and our channels) with recommended actions. You can exit the affected strategy at any time — move funds to another strategy or withdraw to your wallet — and we post updates as the situation develops.

Red Flags to Watch For

  • 🚩 Sudden large APY increases (may indicate exploit)
  • 🚩 Withdrawal delays (check protocol status)
  • 🚩 Unusual Account balance changes (verify transactions)
  • 🚩 Unannounced contract upgrades (should never happen)

If you see any of these: stop new deposits, check official channels, verify on-chain, and contact support.


Next Steps

Ready to start securely? Launch Bundie App